5Viewes
SECURITY VULNERABILITY ANALYSIS IN CYBER PATROL WEB APPLICATION USING OWASP WEB SECURITY TESTING GUIDE (WSTG) METHODOLOGY
Repository Analytics
Statistic Details
0Downloaded
5Accessed per month
1Countries
Loading...
Date
Authors
Samosir, Fikri
Journal Title
Journal ISSN
Volume Title
Publisher
Politeknik Negeri Batam
Abstract
Web applications remain a primary attack vector for data breaches. Consequently, securing internal
systems is as critical as fortifying external perimeters to mitigate insider threats. Web Cyber Patrol, an
internal offensive security platform developed by Seclab, manages highly sensitive organizational data
where any potential breach poses severe operational risks. Furthermore, the application has never
undergone a formal security evaluation, making a comprehensive penetration test an absolute prerequisite
before its operational launch in a production environment. This study aims to perform a thorough security
evaluation to uncover vulnerabilities and ensure the platform's deployment readiness. Utilizing an
evaluative research method with a qualitative approach, this study executed a grey box penetration test
targeting a specific scope of 79 web endpoint. The assessment was strictly guided by the Open Web
Application Security Project (OWASP) Web Security Testing Guide (WSTG) v4.2. Identified vulnerabilities
were categorized by employing the OWASP Top 10 2025 and Common Weakness Enumeration (CWE),
while risk severities were quantified through the Common Vulnerability Scoring System (CVSS) v3.1. The
testing phase uncovered 16 vulnerabilities, predominantly rooted in Insecure Design and Authentication
Failures, with the highest severity classified as Medium risk. Following the delivery of actionable
mitigation recommendations, the development team implemented system patches. A subsequent Retest
validated that all 16 vulnerabilities were successfully resolved, achieving full remediation. This research
emphasizes that internal security tools storing critical data require rigorous testing, and it contributes a
reproducible and systematic framework for applying OWASP WSTG to achieve pre-deployment security
clearance.
Description
Citation
IEEE
